PRIVACY POLICY

1. Introduction

At C-Town Cycle (“we,” “us,” or “our”), accessible at ctowncycle.com, we value your privacy and are firmly committed to protecting your personal data. This Privacy Policy outlines how we collect, use, store, and share your information when you interact with our website and services. We adopt a privacy-first approach that prioritizes data protection principles, transparency, accountability, and user control, in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

2. Scope of Policy and Data Controller Role

This Privacy Policy applies to all users who access or interact with ctowncycle.com, including the online storefront, account services, and customer support. Where personal data is collected through the website or any related services, the data controller for the purposes of applicable data protection law is C-Town Cycle.

For all privacy-related inquiries, C-Town Cycle may be contacted at [email protected].

3. Categories of Data We Process

We may collect and process the following categories of personal data:

a. Usage Data
This includes information about how you use ctowncycle.com, including your IP address, browser type and version, geographic location, referral source, length of visit, page views, session data, and website navigation paths.

b. Account Data
When you register or make a purchase, we collect information you provide for account creation, including your name, email address, billing and shipping address, and phone number.

c. Profile Data
We gather information linked to your preferences, purchasing history, browsing behavior, wishlist items, and saved settings to personalize your experience.

d. Communication Data
This includes records of inquiries you make to our support or customer service teams, including emails, chat transcripts, and contact forms submitted via ctowncycle.com.

e. Technical Data
We collect device-specific metadata such as IP addresses, connection status, operating system, screen resolution, system configurations, and browser fingerprints to ensure compatibility and performance.

f. Transaction Data
We process details related to orders and purchases, including products or services purchased, transaction amounts, delivery address, and payment authorization information. While payment data is processed through secure third-party gateways and not stored directly by us, the associated transaction metadata is maintained.

g. Preference Data
We record and retain user-set preferences related to communication frequency, product interest categories, marketing consents, and opt-in/opt-out choices.

4. Legal Bases for Processing

We process personal data under the following lawful bases:

– Performance of a Contract: Processing necessary for fulfilling a product or service you requested (e.g., product orders or account management).
– Consent: Where required by law, we obtain your consent before processing certain types of personal data (e.g., sending marketing emails or installing non-essential cookies).
– Legitimate Interests: We may process your data for our legitimate interests, such as business analytics, fraud prevention, service optimization, and user experience improvements—always ensuring such interests do not override your rights.
– Legal Obligation: Processing required for compliance with applicable legal or regulatory obligations.

5. Your Rights Under Applicable Laws

Subject to local laws and certain exceptions, individuals have the following rights regarding their personal data:

– Right of Access: To request a copy of the personal data we hold about you.
– Right to Rectification: To correct inaccurate or incomplete personal information.
– Right to Erasure: To request deletion of your data where it is no longer necessary or lawful.
– Right to Restrict Processing: To request limited processing of your data under specific conditions.
– Right to Data Portability: To obtain a copy of your personal data in a structured, commonly used, and machine-readable format for transmission to another data controller.
– Right to Object: To object to certain types of processing, including direct marketing and profiling.
– Right Not to Be Subject to Automated Decision-Making: To request human intervention where decisions are made solely on automation.
– Rights under CCPA: California residents may also request disclosure, access, deletion, and opt-out of the sale of personal information.

To exercise these rights, please contact us at [email protected].

6. Security Measures

We implement industry-standard measures to protect your personal information, including:

– SSL encryption for data transmission.
– Role-based access control to restrict access to sensitive data.
– Routine automated backups and disaster recovery protocols.
– Staff training in data protection and information handling procedures.
– Network security tools including firewalls, anomaly detection, and intrusion prevention.

7. International Data Transfers

Where your personal data is transferred outside of your local jurisdiction—for example, from the European Economic Area to the United States—we ensure that such transfers are lawful under appropriate safeguards. These include:

– Use of the European Commission’s Standard Contractual Clauses;
– Participation in compliance frameworks where applicable;
– Ensuring that data processors maintain adequate levels of protection.

8. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:

– Account Data: Active until closure of the account plus 6 years for compliance and fraud prevention.
– Purchase and Transaction Data: Retained for 7 years to meet accounting and tax obligations.
– Communication Records: Retained for 2 years post-interaction.
– Technical and Usage Data: Aggregated and anonymized where possible and retained for 18 months.
– Marketing or Preference Data: Retained until withdrawal of consent or cancellation of subscription preferences.

9. Cookie Policy

We use cookies and tracking technologies on ctowncycle.com, which fall into the following categories:

– Essential Cookies: Required for the operation and navigation of the site. These cannot be disabled.
– Functional Cookies: Support enhanced functionality and personalization (e.g., language settings, saved preferences).
– Performance & Analytics Cookies: Collect data on website usage, such as Google Analytics, to help us improve user experience.
– Marketing Cookies: Track visits and interactions to provide more relevant advertising on third-party platforms.

10. Cookie Management & Compliance

In line with GDPR and CCPA requirements, users are provided with:

– A cookie banner upon first visit allowing for granular cookie preference settings;
– The ability to change or withdraw cookie consent at any time via our Cookie Settings tool;
– An opt-out mechanism for third-party marketing and remarketing cookies;
– “Do Not Track” and “Global Privacy Control” signal handling where supported.

11. Children’s Privacy

C-Town Cycle does not knowingly collect or solicit personal data from individuals under the age of 13. If we become aware that personal data of a child under 13 has been collected without verifiable parental consent, we will take steps to delete such information promptly. If you believe a child has provided us their personal data, please contact us at [email protected].

12. Policy Updates

We may update this Privacy Policy from time to time to reflect changes in applicable laws, technological advances, or operational practices. Substantive changes will be communicated via notices on ctowncycle.com or directly to users where applicable. Continued use of our services constitutes acceptance of the updated policy.

13. Contact

If you have any questions, data access requests, or concerns regarding this Privacy Policy or our data practices, please contact:

Privacy Officer
C-Town Cycle
Email: [email protected]

We are committed to complying with all applicable privacy regulations and ensuring that your personal data is handled responsibly and transparently. For any inquiries related to your data and privacy rights, please do not hesitate to reach out to us.